1. What we collect
We collect information you submit directly, including contact details, website and product URLs, diagnostic inputs, support context, account and organization details, project content, approvals, and billing or subscription details returned by our payment provider.
We also process information generated while a requested feature operates. Depending on the feature, this can include network and request metadata such as an IP address for security and rate limiting; authentication and session records; publicly available page content, response headers, and scan evidence gathered for a diagnostic; and job, audit, error, email-delivery, payment, subscription, connector, and webhook status records. Where tracking described below is active, it can also include consent and browser privacy-signal state, visitor and session identifiers, page and referrer paths, event timestamps, and bounded campaign or advertising-click attribution fields.
We do not buy personal data, and we do not sell personal data.
2. How we use it
We use your information to respond to inquiries, run the diagnostic you request, scope and deliver your build, operate hosted hubs and monitoring, process billing, provide support, secure the service, enforce usage limits, investigate failures, and maintain delivery and approval records. Approved, published content is public by design; drafts and internal project data are limited to authorized workspace users, our service operations, and the processors needed to provide the service.
A successfully completed diagnostic may also contribute one irreversible aggregate metrics row for directional research. That row contains structural scores, inferred business type, schema-presence flags, scan mode, counts, and date only; it contains no account, organization, project, name, URL, contact field, source text, or free text. A source-side receipt prevents retry duplication, while the aggregate row is not linked back to the source run. Legacy rows without that receipt are excluded from public summaries.
3. Cookies & tracking
Tracking is limited by surface and configuration. Specifically:
- Authenticated app features may use necessary session cookies for login, security, and connector flows.
- The optional RevenueLoop first-party tracking script is installed by a customer on a customer-owned site. Installation alone does not activate collection: the host site must first signal affirmative analytics consent. Until then, the script remains inactive and does not create its visitor or session identifiers or send tracking events.
- RevenueLoop treats Global Privacy Control and Do Not Track browser signals as a denial. A denial or a later consent withdrawal keeps collection off and clears the script's first-party visitor and session cookies.
- When RevenueLoop collection is active, stored page and referrer URLs are reduced to origin and path; credentials, query strings, and fragments are omitted. Bounded UTM fields and supported advertising click identifiers may be captured separately for attribution.
- Blue Ninja acquisition pages may send first-party page and interaction telemetry in the production environment. An optional marketing analytics container loads only when a valid container is configured by the site operator. These components remain off for pages with URL fragments or query fields outside the bounded acquisition-attribution allowlist, so diagnostic, checkout, and result capabilities are not exposed to them.
- Company marketing analytics are not mounted in authenticated application pages, authentication or onboarding flows, customer support hubs, or embedded EntityAgent widgets.
- On the production Vercel deployment, anonymous performance measurements may run across product and public surfaces so we can monitor Core Web Vitals. Query strings, fragments, credentials, and dynamic record identifiers are removed before delivery; the measurements are not used to reconstruct a browsing session or identify an individual.
4. Storage & sharing
Data is stored with our infrastructure providers (hosting, database, email, and payment processing) under their security controls. We share data with those processors only as needed to run the service, and with the AI-engine, commerce, connector, and analytics providers used or configured for the applicable feature. Provider identifiers and delivery status may be retained so we can reconcile work and failures. We never sell your data to advertisers or brokers.
5. Your rights & choices
You can request access to, correction of, or deletion of personal data associated with you. Account owners can export supported project artifacts and manage published project content. Privacy requests run through a reviewed workflow with a receipt because billing, security, contractual, dispute, or other required records may need retention or redaction instead of immediate deletion. To make a request, contact hello@entitymesh.io.
6. Retention
Retention depends on the record and why it exists. Active account and project data is kept while needed to provide the service. Some transient tracking, query, model-response, and operational records use shorter scheduled retention windows. Billing, payment, privacy-request, security, approval, published-version, and contractual delivery records may require longer retention or a reviewed redaction process. We delete, anonymize, redact, or retain records according to the applicable operational schedule and approved hold.
7. Changes & contact
We may update this policy; the “last updated” date above reflects the current version. Questions can go to hello@entitymesh.io.